<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Spyware on OINK</title><link>https://lxghost.github.io/zh/tags/spyware/</link><description>Recent content in Spyware on OINK</description><generator>Hugo</generator><language>zh-CN</language><lastBuildDate>Tue, 08 Sep 2026 00:40:17 +0800</lastBuildDate><atom:link href="https://lxghost.github.io/zh/tags/spyware/index.xml" rel="self" type="application/rss+xml"/><item><title>packagist themes ios spyware</title><link>https://lxghost.github.io/zh/blog/threat/packagist-themes-ios-spyware/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lxghost.github.io/zh/blog/threat/packagist-themes-ios-spyware/</guid><description>&lt;h2 id="执行摘要"&gt;执行摘要&#10;&lt;/h2&gt;&#10;&lt;p&gt;&lt;a href="https://lxghost.github.io/static/view/packagist-themes-ios-spyware.html"&gt;可视化报告&lt;/a&gt;&#10;Socket 发布的研究报告披露了一起针对 &lt;strong&gt;Packagist / Composer 软件供应链&lt;/strong&gt;的恶意软件投递活动。&lt;/p&gt;&#10;&lt;p&gt;攻击者在多个 PHP Composer 主题包中植入恶意 JavaScript。这些主题主要用于基于 &lt;strong&gt;OphimCMS&lt;/strong&gt; 和 &lt;strong&gt;KKPhim&lt;/strong&gt; 的电影、漫画流媒体网站。网站管理员安装受污染的主题后，恶意 JavaScript 会被部署到生产网站，并自动提供给访问网站的终端用户。&lt;/p&gt;</description></item></channel></rss>